PT-2005-5569 · Pcre+1 · Libpcre3-Dev+9

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2018-10-16

·

CVE-2007-1659

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libpcrecpp0 versions (affected versions not specified) libpcre3 versions (affected versions not specified) libpcre versions prior to 7.3-r1 pcre-32bit versions (affected versions not specified) pcregrep versions (affected versions not specified) pcre versions (affected versions not specified) libpcre3-dev versions (affected versions not specified) pgrep versions (affected versions not specified) pcre-devel versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the PCRE library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities allow context-dependent attackers to cause a denial of service and possibly execute arbitrary code via regex patterns containing unmatched "QE" sequences with orphan "E" codes.
Recommendations For libpcrecpp0, update to a version that contains a fix for this issue. For libpcre3, update to a version that contains a fix for this issue. For libpcre, update to version 7.3-r1 or later. For pcre-32bit, update to a version that contains a fix for this issue. For pcregrep, update to a version that contains a fix for this issue. For pcre, update to a version that contains a fix for this issue. For libpcre3-dev, update to a version that contains a fix for this issue. For pgrep, update to a version that contains a fix for this issue. For pcre-devel, update to a version that contains a fix for this issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02588
BDU:2015-02589
BDU:2015-02590
BDU:2015-02591
BDU:2015-03061
BDU:2015-04723
BDU:2015-04724
BDU:2015-04725
BDU:2015-09569
CVE-2007-1659
DSA-1399-1
DSA-1570-1
DTSA-77-1
RHSA-2007:0967
RHSA-2007:1068
RHSA-2007_0967
RHSA-2007_1068

Affected Products

Red Hat
Libpcre
Libpcre3
Libpcre3-Dev
Libpcrecpp0
Pcre
Pcre-32Bit
Pcre-Devel
Pcregrep
Pgrep